CVE Published: 17/04/2024 |
CVE Updated: 24/11/2024 |
CVE Year: 2024 Source: redhat |
Vendor: |
Product: Status : PUBLISHED
CVE-2024-1249 Description
A flaw was found in Keycloak\'s OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application\'s availability without proper origin validation for incoming messages.